Aggregator
黑客是场电子梦
Flask(Jinja2) 服务端模板注入漏洞(SSTI) - 淚笑
That’s a Wrap! Read the Top Technology Takeaways From CES 2019
The sun has finally set on The International Consumer Electronics Show (CES) in Las Vegas. Every year, practically everyone in...
The post That’s a Wrap! Read the Top Technology Takeaways From CES 2019 appeared first on McAfee Blog.
KoiPhish - The Beautiful Phishing Proxy
KoiPhish is a simple yet beautiful relay proxy idea.
The idea for this little project goes back many years. Since I started learning Golang I figured it would be good exercise to finally go ahead an implement it. So, last December during the 35C3 (which is always inspiring congress) I wrote it up.
It relays requests a client makes to the KoiPish to the actual target and responses are sent back to the client. On the way in and out common links are overwritten in order to not break the user experience and functionality.
rsync 未授权访问漏洞 - 淚笑
How We Patch Vulnerabilities at F5
How We Patch Vulnerabilities at F5
code-breaking easy部分题目writeup
Preparing for Y2038 (Already?!)
PHP-FPM Fastcgi 未授权访问漏洞 - 淚笑
Update Your Trust Model Before the Public Does It for You
Update Your Trust Model Before the Public Does It for You
January 2019 Security Update Release
January 2019 Security Update Release
统计学2:现代概率
现代概率的一大特征是概率不确定性.古代概率研究的骰子可以认为每面的概率是1/6, 但是统计天气的时候, 就没有理由认为晴天和雨天的概率都是1/2.
From the Core to the Edge: 3 Security Imperatives and the Evolving Digital Topology
McPivot and useful LLDB commands
Just a list of useful notes when dealing with Macs. I’m pretty new to Macs and there might be other, better solutions to the challenges I had to sovle but these worked for me and I’m learning. :)
Pivoting between accounts and keychain issuesAfter pivoting on a target host and elevating to root it seems not possible to gain access to other keychains easily. It requires to know the password of the other account still. Just running